Privacy Policy
Last updated: June 2026
Information We Collect
Building Data: OpenStoop (operated by OpenStoop LLC) aggregates publicly available building data from New York City government sources including HPD, DOB, DOF, ACRIS, FDNY, and the 311 system. Property-owner names and recorded property and financial documents shown are part of the public record.
Email Addresses: When you access building reports or subscribe to updates, we collect your email address. We use it to deliver the service you requested and occasional product updates. We do not sell your email. We share it only with the service providers that help us operate OpenStoop (listed below) and never with third parties for their own marketing.
Payment Information: When you purchase a building report, payment is processed securely by Stripe. OpenStoop does not receive, store, or have access to your credit card number. We receive only a transaction confirmation, your email, and a Stripe customer ID.
Analytics: We collect standard web analytics (page views, referrers, device type) to improve the service. We do not use third-party advertising trackers.
Public Records & Removal Requests
Much of the information on OpenStoop — including property-owner names, violation histories, and recorded financial documents — comes from records that New York City makes publicly available (HPD, DOB, DOF, ACRIS, FDNY, and 311). Republishing public-record information is lawful, and we do not remove, hide, or alter public-record data on request.
If you believe a government record is inaccurate, the correction must be made with the source agency (for example, NYC ACRIS for ownership and financial documents, or HPD for violations). Once the city updates its records, the change is reflected on OpenStoop after our next data refresh.
This is separate from the personal account information you provide directly to us (such as your email address), which you may ask us to delete — see “Account Data Deletion” below.
Cookies
OpenStoop uses a small number of functional cookies: an email verification cookie (os_email), a view-metering cookie (os_meter) that records buildings you've already viewed to manage free access to maintain your session, and standard analytics cookies. We do not use advertising or tracking cookies.
Not a Consumer Report
OpenStoop building reports are informational tools based on public records and do not constitute “consumer reports” as defined by the Fair Credit Reporting Act (FCRA). See our Terms of Service for details.
California Residents (CCPA/CPRA)
If you are a California resident, you may have the right to request access to or deletion of the personal information we hold about you, and to opt out of its sale or sharing. These rights apply to the personal information you provide to us (such as your email address). They do not apply to information that is lawfully made available from federal, state, or local government records, which the CCPA expressly exempts from these rights. We do not sell the personal account information you provide to us. To exercise your rights, email hello@openstoop.com; we will respond within the time required by law.
Account Data Deletion
You may request deletion of the personal account information you provided to us — your email address, subscription preferences, and any Stripe customer reference — by contacting hello@openstoop.com. We will verify the request and delete that information within the timeframe required by applicable law. This does not apply to public-record building data (see “Public Records & Removal Requests” above), which is not personal account data and is not removed on request.
API Usage
API access may be subject to rate limiting and usage tracking. API keys, if issued, are stored securely and used solely for authentication and usage management.
Third-Party Service Providers
We use the following third-party services to operate OpenStoop:
- Stripe — payment processing (privacy policy)
- Vercel — website hosting (privacy policy)
- PostHog — product analytics (privacy policy)
- Cloudflare — CDN and DNS (privacy policy)
- Resend — transactional email (privacy policy)
European Users (GDPR)
If you are located in the European Economic Area or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, erase, restrict processing of, and port the personal account data you provide to us. Our legal basis for processing the account data you provide is legitimate interest (providing the service) and, where applicable, your consent. Information drawn from publicly available government records is processed on the basis of legitimate interest and the public availability of those records, and corrections to it are made at the source agency as described above. To exercise your rights, contact hello@openstoop.com.
Data Security & Breach Notification
We implement reasonable technical and organizational measures to protect your personal information. In the event of a data breach affecting your personal information, we will notify affected users and relevant authorities as required by applicable law.
Contact
For privacy-related inquiries, contact us at hello@openstoop.com.